PT-2000-1690 · Lyris · Lyris Listmanager

Publicado

2000-10-20

·

Atualizado

2008-09-05

·

CVE-2000-0758

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Lyris List Manager versions 3 and 4
Description The issue allows list subscribers to gain administrative access through the web interface by modifying the value of the list admin hidden form field.
Recommendations For Lyris List Manager versions 3 and 4, consider restricting access to the web interface until a fix is available, and avoid using the list admin hidden form field to prevent exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2000-0758

Produtos afetados

Lyris Listmanager